Paper 2026/2180

Gaussian Kernel Lattices and Smoothing Bounds from Theta Integrals

Samed Düzlü, Technical University of Munich
Nihar Gargava, Université Paris-Saclay
Erkan Tairi, University of California, Berkeley
Abstract

A Gaussian leftover hash lemma (LHL) states that, for a matrix $\mathbf{X}$ with discrete Gaussian columns and a sufficiently wide Gaussian vector $\mathbf{v}$, the product $\mathbf{X}\mathbf{v}$ is close to a discrete Gaussian. Over the integers this is a classical tool, and Albrecht-Felderhoff-Lai-Lapiha-Woo (EUROCRYPT'26) recently extended it to modules over a number field $K$ of degree $d$. In every version, the lemma rests on two facts about the kernel lattice of $\mathbf{X}$: that $\mathbf{X}$ is surjective, and that the smoothing parameter of the kernel is small. We prove both facts with a single analytic estimate. An exact identity expresses the Gaussian mass of the dual kernel, multiplied by the index of the image of $\mathbf{X}$, as an integral of one-dimensional periodic Gaussian sums over a torus. Bounding this integral below two forces the index to be one, which is surjectivity, and bounds the smoothing parameter at the same time. No separate surjectivity argument and no GRH are needed. For smoothing error $2^{-\lambda}$ the smoothing parameter is $O_K(\sqrt\lambda)$ with explicit constants, once $\mathbf{X}$ has $m\gtrsim dr\ln(srm)$ columns, and a deterministic lower bound shows that this order is optimal. The width $s$ of the matrix enters only through the number of columns. Over power-of-two cyclotomic fields the theorem even applies to matrices whose integer coefficients follow a discrete Gaussian of width one. In the SIS-to-$k$-SIS reduction of Albrecht et al. (EUROCRYPT'26), the new bound lowers the hint width from $d^{39/2}\lambda^{9/2}$ to $d^{3/2}\lambda^{3/2}$ and the norm loss from $d^{41/2}\lambda^{5}$ to $d^{3/2}\lambda^{2}$, up to logarithmic factors. Additionally, we also formalized the main results of the paper in Lean.

Metadata
Available format(s)
PDF
Category
Foundations
Publication info
Preprint.
Keywords
leftover hash lemmadiscrete Gaussianlattice-based cryptographypost-quantum
Contact author(s)
samed duzlu @ tum de
nihar gargava @ universite-paris-saclay fr
erkan tairi @ berkeley edu
History
2026-09-26: approved
2026-09-23: received
See all versions
Short URL
https://ia.cr/2026/2180
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/2180,
      author = {Samed Düzlü and Nihar Gargava and Erkan Tairi},
      title = {Gaussian Kernel Lattices and Smoothing Bounds from Theta Integrals},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2180},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2180}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.